Windows
Analysis Report
wsl-gvproxy.exe
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
PE file contains more sections than normal
Potential time zone aware malware
Program does not show much activity (idle)
PE file contains sections with non-standard names
Classification
- System is w10x64
wsl-gvproxy.exe (PID: 4536 cmdline:
"C:\Users\ user\Deskt op\wsl-gvp roxy.exe" -install MD5: 0F9947DDAB6BF8D7A6B350EC8395985E)
wsl-gvproxy.exe (PID: 2228 cmdline:
"C:\Users\ user\Deskt op\wsl-gvp roxy.exe" /install MD5: 0F9947DDAB6BF8D7A6B350EC8395985E)
wsl-gvproxy.exe (PID: 2148 cmdline:
"C:\Users\ user\Deskt op\wsl-gvp roxy.exe" /load MD5: 0F9947DDAB6BF8D7A6B350EC8395985E)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • Compliance
- • System Summary
- • Data Obfuscation
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Anti Debugging
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | String found in binary or memory: |